Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F09218538C29624FB22542D4B44E3B1499CA9D3F86F2CE54E4F7E3D0AB758E4D326268 |
|
CONTENT
ssdeep
|
192:aU9gPFF9ccDzodtVsF/Jc6u6euvfGjdw89H:d9I7DAHYVRv2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f906d8ab16f9a458 |
|
VISUAL
aHash
|
0000008000fbffc8 |
|
VISUAL
dHash
|
29009100120b1b9a |
|
VISUAL
wHash
|
940040c0e0fffffe |
|
VISUAL
colorHash
|
30401010000 |
|
VISUAL
cropResistant
|
b1b3b268e83910b0,ace46b3996909493,17d7ebeeedf1a6cc,15c493333333b133,6c69cadc9eee6e4e,29009100120b1b9a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.